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Foreword 



This Technical Specification (TS) has been produced by ETSI 3rd Generation Partnership Project (3GPP). 

The present document may refer to technical specifications or reports using their 3GPP identities, UMTS identities or 
GSM identities. These should be interpreted as being references to the corresponding ETSI deliverables. 

The cross reference between GSM, UMTS, 3 GPP and ETSI identities can be found under 
http ://webapp . etsi .org/key/query f orm. asp . 

The 3 GPP Confidentiality and Integrity Algorithms f8 & f9 have been developed through the collaborative efforts of the 
European Telecommunications Standards Institute (ETSI), the Association of Radio Industries and Businesses (ARIB), 
the Telecommunications Technology Association (TTA), the Tl Committee. 

The f8 & f9 Algorithms Specifications may be used only for the development and operation of 3G Mobile 
Communications and services. Every Beneficiary must sign a Restricted Usage Undertaking with the Custodian and 
demonstrate that he fulfils the approval criteria specified in the Restricted Usage Undertaking. 

Furthermore, Mitsubishi Electric Corporation holds essential patents on the Algorithms. The Beneficiary must get a 
separate IPR License Agreement from Mitsubishi Electronic Corporation Japan. 

For details of licensing procedures, contact ETSI, ARIB, TTA or Tl. 

The contents of the present document are subject to continuing work within the TSG and may change following formal 
TSG approval. Should the TSG modify the contents of the present document, it will be re-released by the TSG with an 
identifying change of release date and an increase in version number as follows: 

Version x.y.z 

where: 

X the first digit: 

1 presented to TSG for information; 

2 presented to TSG for approval; 

3 or greater indicates TSG approved document under change control. 

y the second digit is incremented for all changes of substance, i.e. technical enhancements, corrections, 
updates, etc. 

z the third digit is incremented when editorial only changes have been incorporated in the document. 



Introduction 



This specification has been prepared by the 3GPP Task Force, and gives detailed test data for implementors of the 
algorithm set. It provides visibility of the internal state of the algorithm to aid in the realisation of the algorithms. 

This document is the third of four, which between them form the entire specification of the 3 GPP Confidentiality and 
Integrity Algorithms: 

- 3GPP TS 35.201: "3rd Generation Partnership Project; Technical Specification Group Services and System 
Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity Algorithms; Document l:f8 and 
f9 Specification" . 

- 3GPP TS 35.202: "3rd Generation Partnership Project; Technical Specification Group Services and System 
Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity Algorithms; Document 2: 
KASUMI Specification". 

- 3GPP TS 35.203: "3rd Generation Partnership Project; Technical Specification Group Services and 
System Aspects; 3G Security; Specification of the 3GPP Confidentiahty and Integrity Algorithms; 
Document 3: Implementors' Test Data". 

- 3GPP TS 35.204: "3rd Generation Partnership Project; Technical Specification Group Services and System 
Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity Algorithms; Document 4: Design 
Conformance Test Data" . 
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This document is purely informative. The normative part of the specification of the /^ (confidentiaHty) and the/P 
(integrity) algorithms is in the main body of Document 1 . The normative part of the specification of KASUMI is found 
in document 2. 
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Scope 



This specification gives detailed test data for implementors of the algorithm set. It provides visibility of the internal 
state of the algorithm to aid in the realisation of the algorithms. 



1 Outline of the implementors' test data 

Section 2 introduces the algorithms and describes the notation used in the subsequent sections. 

Section 3 provides test data for KASUMI. 

Section 4 provides test data for the Confidentiality Algorithm F8. 

Section 5 provides test data for the Integrity Algorithm F9. 

1.1 References 

The following documents contain provisions which, through reference in this text, constitute provisions of the present 
document. 

• References are either specific (identified by date of publication, edition number, version number, etc.) or 
non-specific. 

• For a specific reference, subsequent revisions do not apply. 

• For a non-specific reference, the latest version applies. In the case of a reference to a 3GPP document (including 
a GSM document), a non-specific reference implicitly refers to the latest version of that document in the same 
Release as the present document. 

[1] 3GPP TS 33.102 version 3.2.0: "3rd Generation Partnership Project; Technical Specification 

Group Services and System Aspects; 3G Security; Security Architecture". 

[2] 3GPP TS 33.105 version 3.1.0: "3rd Generation Partnership Project; Technical Specification 

Group Services and System Aspects; 3G Security; Cryptographic Algorithm Requirements". 

[3] 3GPP TS 35.201: "3rd Generation Partnership Project; Technical Specification Group Services 

and System Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity 
Algorithms; Document 1: f8 and f9 Specification". 

[4] 3 GPP TS 35.202: "3rd Generation Partnership Project; Technical Specification Group Services 

and System Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity 
Algorithms; Document 2: KASUMI Specification". 

[5] 3GPP TS 35.203: "3rd Generation Partnership Project; Technical Specification Group Services 

and System Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity 
Algorithms; Document 3: Implementors' Test Data". 

[6] 3 GPP TS 35.204: "3rd Generation Partnership Project; Technical Specification Group Services 

and System Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity 
Algorithms; Document 4: Design Conformance Test Data". 

[7] ISO/IEC 9797-1 : 1999: "Information technology - Security techniques - Message Authentication 

Codes (MACs)". 
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Introductory information 



2.1 Introduction 

Within the security architecture of the 3GPP system there are two standardised algorithms; a confidentiaHty algorithm 
f8, and an integrity algorithm /9. These algorithms are specified in a companion document [3]. Each of these algorithms 
is based on the KASUMI algorithm that is specified in [4] . 

To assist implementors with their realisation of the algorithm set this document provides test data for these algorithms 
along with extensive detail of the internal states of the algorithms as they process the given input data. 

Final testing of the algorithms should be performed using the test data sets given in the "Design Conformance" 
companion document [6] . 

2.2 Radix 

Unless stated otherwise, all test data values presented in this document are in hexadecimal. 



2.3 Bit/Byte ordering 



All data variables in this specification are presented with the most significant bit (or byte) on the left hand side and the 
least significant bit (or byte) on the right hand side. Where a variable is broken down into a number of sub-strings, the 
left most (most significant) sub-string is numbered 1, the next most significant is numbered 2 and so on through to the 
least significant. 

For example the 128-kit key K is subdivided into eight 16-bit substrings K1...K8 so if we have a key 
K = 0123456789ABCDEFFEDCBA9876543210 

we have: 

Kl = 0123, K2 = 561S, K3 = 9 ABC, ii:^ = 3210. 

2.4 Presentation of input/output data 

The basic data processed by the/5 and/P algorithms are bit streams. In general in this document the data is presented 
in hexadecimal format as bytes, thus the last byte shown as part of an input or output data stream may include between 
and 7 bits that are ignored once the LENGTH parameter is taken into account. (The least significant bits of the byte 
are ignored). 



3 KASUMI 

3.1 Overview 

The test data sets presented here are for the KASUMI block cipher algorithm. 

3.2 Format 

Each test set starts by showing the input and output data values. This is followed by a table showing the internal sub- 
keys that are derived from the 128-bit key. 

For each round the inputs and outputs are shown for the FL, FO and FI functions in the form: 
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Round i 




FLi ( input, KLli, KL2i ) 


->output 


FOi ( input ) ->output 




FIil( input, Klil ) -> 


output 


FIi2( input, KIi2 ) -> 


output 


FIi3( input, KIi3 ) -> 


output 



In addition, for the first two rounds, the internal states of the 7-bit and 9-bit data paths within the FI function are shown 
in the form: 



seven 17-> 0C-> 47-> 72-> 6C-> 21 
nine 19E->05C->04B->1BB->1BF->1CD 



where the first value shown is the value derived from the 16-bit input, and the subsequent values are the changes that 
occur as the data passes through the function down the respective 7-bit or 9-bit data paths, i.e. The values shown 
following the input value are: 

result of S-box lookup, 
XOR with other half, 
XOR with key, 
S-box lookup, 
XOR with other half. 



3.3 



Test Set 1 



Key 

input 

output 



2B D6 45 9F 82 C5 B3 00 95 2C 49 10 48 81 FF 4£ 
EA 02 47 14 AD 5C 4D 84 
DF IF 9B 25 IC OB F4 5F 



Key schedule : 





1 


2 


3 


4 


5 


6 


7 


8 


KLi1 


57AC 


8B3E 


058B 


6601 


2A59 


9220 


9102 


FE91 


KLi2 


0B6E 


7EEF 


6BF0 


F388 


3ED5 


CD58 


2AF5 


00F8 


K0i1 


B3E8 


58B0 


6016 


A592 


2209 


1029 


E91F 


7AC5 


K0i2 


1049 


8148 


48FF 


D62B 


9F45 


C582 


00B3 


2C95 


K0i3 


2910 


1FE9 


C57A 


E8B3 


B058 


1660 


92A5 


0922 


Kli1 


6BF0 


F388 


3ED5 


CD58 


2AF5 


00F8 


0B6E 


7EEF 


Kli2 


7EEF 


6BF0 


F388 


3ED5 


CD58 


2AF5 


00F8 


0B6E 


Kli3 


CD58 


2AF5 


00F8 


0B6E 


7EEF 


6BF0 


F388 


3ED5 



Input: EA024714 AD5C4D84 

Round 1 
FLI (EA024714, 57AC, 0B6E) ->7CFFC314 
FOI (7CFFC314) ->58871737 
Fill (CF17, 6BF0) ->43CD 

seven 17-> 0C-> 47-> 72-> 6C-> 21 
nine 19E->05C->04B->1BB->1BF->1CD 
FI12 (D35D, 7EEF) ->D85E 

seven 5D-> 61-> 3E-> 01-> 32-> 6C 
nine lA6->0 82->0DF->03 0->05F->05E 
FI13 (A9C9,CD58) ->4FB0 

seven 49-> 63-> 52-> 34-> 17-> 27 
nine 153->1F8->1B1->0E9->184->1B0 



Round 2 
F02 (F5DB5AB3) ->03E715B9 
FI21 (AD6B,F3 88) ->E2FC 

seven 6B-> 31-> 4F-> 36-> 0D-> 71 
nine 15A->015->0 7E->1F6->0CA->0FC 
FI22 (DBFB, 6BF0) - >BBA8 

seven 7B-> 29-> 75-> 40-> 75-> 5D 
nine 1B7->12 7->15C->0AC->1E8->1A8 
FI2 3 (A7A6,2AF5) ->165E 

seven 26-> 3A-> 73-> 66-> 55-> OB 
nine 14F->06F->04 9->0BC->03 8->05E 
FL2 (03E715B9, 8B3E, 7EEF) ->FC1913F5 



Round 3 
FL3 (161B54E1, 058B,6BF0) ■ 



>E9F55CF7 
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F03 (E9F55CF7) ->F9C9DB3F 

FI31 (8 9E3,3ED5) ->4C63 

seven 63-> 2D-> 54-> 4B-> 45-> 26 
nine 113->19A->lF9->12C->02 8->0 63 

FI32 (14 08,F3 88) ->E95D 

seven 08-> 26-> 02-> 7B-> 29-> 74 
nine 02 8->02C->024->lAC->12 6->15D 

FI3 3 (D5EE, 0F8) ->22F6 

seven 6E-> 73-> 5B-> 5B-> 67-> 11 
nine lAB->046->02 8->0D0->0AD->0F6 

Round 4 
F04 (0C12818C) ->F9C83A1A 
FI41 (A980,CD58) ->4D43 

seven 00-> 36-> 4E-> 28-> 65-> 26 
nine 153->1F8->1F8->0A0->16B->14 3 
FI4 2 (57A7, 3ED5) ->35 07 

seven 27-> 30-> 72-> 6D-> lD-> lA 
nine 0AF->0E5->0C2->017->16A->10 7 
FI43 (247C, 0B6E) ->C3D2 

seven 7C-> 58-> 54-> 51-> 33-> 61 
nine 04 8->0F0->0 8C->lE2->183->lD2 
FL4 (F9C83A1A,6601,F388) ->0EFDFA1A 

Round 5 
FL5 (18E6AEFB,2A59,3ED5) ->6519BE7B 
F05 (6519BE7B) ->D1FAD9E0 
FI51 (4 710, 2AF5) ->781A 

seven 10-> 37-> lD-> 08-> 26-> 3C 
nine 08E->1BA->1AA->15F->012->01A 
FI52 (213E,CD58) ->179B 

seven 3E-> 69-> 5C-> 3A-> 10-> OB 
nine 042->18B->lB5->0ED->lAl->19B 
FI53 (763 9, 7EEF) ->0 81A 

seven 39-> 01-> 73-> 4C-> lE-> 04 
nine 0EC->lCB->lF2->llD->056->01A 

Round 6 
F06 (DDE8586C) ->DD0B619B 
FI61 (CDCl, 00F8) ->8FF4 

seven 41-> 74 -> 51-> 51-> 33-> 47 
nine 19B->0E4->0A5->05D->1A5->1F4 
FI62 (9DEE, 2AF5) ->0A93 

seven 6E-> 73-> ll-> 04-> 16-> 05 
nine 13B->0 0C->062->097->097->093 
FI63 (C1F8,6BF0) ->BC90 

seven 78-> 2A-> 42-> 77-> 4E-> 5E 
nine 183->090->0E8->118->0E7->090 
FL6 (DD0B619B, 9220, CD58) ->46BE419A 

Round 7 
FL7 (5E5 8EF61,9102,2AF5) ->81B3CF61 
F07 (81B3CF61) ->C1E3AC33 
FI71 (68AC, 0B6E) ->EBA4 

seven 2C-> 68-> lA-> lF-> 51-> 75 
nine 0D1->0DE->0F2->19C->1BB->1A4 
FI72 (CFD2, 00F8) ->E526 

seven 52-> ll-> 57-> 57-> 54-> 72 
nine 19F->194->1C6->13E->171->12 6 
FI73 (B660,F388) ->6DD0 

seven 60-> 66-> 19-> 60-> 66-> 36 
nine 16C->01F->0 7F->1F7->1B0->1D0 

Round 8 
F08 (1C0BF45F) ->68BFA566 
FI81 (66CE, 7EEF) ->DB25 

seven 4E-> 7E-> 0D-> 32-> 48-> 6D 
nine 0CD->03D->0 73->0 9C->117->12 5 
FI82 (D8CA, 0B6E) ->47C5 

seven 4A-> 56-> 65-> 60-> 66-> 23 
nine 1B1->179->13 3->05D->1A5->1C5 
FI83 (2 65 8, 3ED5) ->CDD9 

seven 58-> 5B-> 15-> 0A-> 3F-> 66 
nine 04C->196->1CE->11B->1D3->1D9 
FL8 (6 8BFA5 6 6,FE91, 0F8 ) - >814 7 7444 
Output: DF1F9B25 1C0BF45F 
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3.4 



Test Set 2 



Key 

input 

output 



8C E3 3E 2C C3 CO B5 FC 
D3 C5 D5 92 32 7F Bl IC 
DE 55 19 88 CE B2 F9 B7 



IF 3D E8 A6 DC 66 Bl F3 



Key schedule : 





1 


2 


3 


4 


5 


6 


7 


8 


KLiI 


19C7 


7C58 


8781 


6BF9 


3E7A 


D14D 


B8CD 


63E7 


KLi2 


4A6B 


7813 


E1E1 


523E 


AA32 


83E3 


8DC0 


7B4B 


KOil 


C587 


7818 


BF96 


E7A3 


14DD 


8CDB 


3E76 


9C71 


K0i2 


A6E8 


66DC 


F3B1 


E38C 


2C3E 


C0C3 


FCB5 


3D1F 


K0i3 


DB8C 


763E 


71 9C 


87C5 


1878 


96BF 


A3E7 


DD14 


Klil 


E1E1 


523E 


AA32 


83E3 


8DC0 


7B4B 


4A6B 


7813 


Kli2 


7813 


E1E1 


523E 


AA32 


83E3 


8DC0 


7B4B 


4A6B 


Kli3 


83E3 


8DC0 


7B4B 


4A6B 


7813 


E1E1 


523E 


AA32 



Input: D3C5D592 327FB11C 

Round 1 
FLl (D3C5D592, 19C7,4A6B) ->2F32F618 
FOl (2F32F618) ->9F6FAB3F 
Fill (EAB5,E1E1) ->9A6B 

seven 35-> 6D-> 78-> 08-> 26-> 4D 
nine lD5->0A0->0 95->174->0 63->0 6B 
FI12 (5 0F0,7813) ->F31C 

seven 70-> 40-> 14-> 28-> 65-> 79 
nine 0A1->124->154->14 7->134->11C 
FI13 (B7FF, 83E3) ->34 5 

seven 7F-> 03-> 28-> 69-> 4A-> lA 
nine 16F->054->02B->lC8->03 9->05 

Round 2 
F02 (AD101A23) ->5BBD1022 
FI21 (D5 8,52 3E) ->E4 6B 

seven 08-> 26-> 35-> lC-> 19-> 72 
nine lAA->llB->113->12D->077->06B 
FI22 (7CFF,E1E1) ->A5F5 

seven 7F-> 03-> 62-> 12-> 27-> 52 
nine 0F9->llE->161->08 0->lE7->lF5 
FI23 (8876, 8DC0) ->4B9F 

seven 76-> 24-> 60-> 26-> 3A-> 25 
nine 110->032->044->184->lB9->19F 
FL2 (5BBD1022, 7C58, 7813) ->AB9AA012 

Round 3 
FL3 (785F75 8 0,8 781,E1E1) ->93 98 75 82 
F03 (93987582) ->109659D3 
FI31 (2C0E,AA32) ->D87A 

seven 0E-> 7B-> 51-> 04-> 16-> 6C 
nine 058->0A4->0AA->098->07E->07A 
FI32 (8633,523E) ->BD6E 

seven 33-> 3D-> 0E-> 27-> 30-> 5E 
nine 10C->10 0->133->10D->14 9->16E 
FI33 (DC64, 7B4B) ->4945 

seven 64-> 4B-> 60-> 5D-> 61-> 24 
nine 1B8->1CF->1AB->0E0->118->14 5 

Round 4 
F04 (BD8643F0) ->CA56843A 
FI41 (5A2 5,83E3) ->5709 

seven 25-> 3C-> 44-> 05-> 22-> 2B 
nine 0B4->15D->178->0 9B->10C->10 9 
FI42 (A07C,AA32) - >DEAF 

seven 7C-> 58-> 25-> 70-> 40-> 6F 
nine 14 0->0 01->07D->04F->0DF->0AF 
FI43 (933C,4A6B) ->4E6C 

seven 3C-> 52-> 41-> 64-> 4B-> 27 
nine 126->lAF->193->lF8->0 08->06C 
FL4 (CA56843A, 6BF9, 523E) ->6F2A109A 
Round 5 
FL5 (1775651A,3E7A,AA32) ->C08049FA 
F05 (C08049FA) ->C9D692DD 
FI51 (D45D, 8DC0) ->AB91 
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seven 5D-> 61-> 2A- 
nine 1A8->016->04B- 
FI52 (65C4, 83E3) ->2BBD 
seven 44-> 59-> 6B- 
nine 0CB->1F6->1B2- 
FI53 (FA13,7813) ->5B0B 
seven 13-> 72-> 34- 
nine 1F4->155->146- 
Round 6 
F06 (7450D12D) ->F6FA9BBE 
FI61 (F8 8B,7B4B) ->5654 
seven 0B-> 5D-> 14- 
nine lFl->042->049- 
FI62 (11EE,8DC0) ->7183 
seven 6E-> 73-> 38- 
nine 023->025->04B- 
FI63 (11C6,E1E1) ->6D44 
seven 46-> 00-> 63- 
nine 023->025->063- 
FL6 (F6FA9BBE,D14D, 83E3) - 
Round 7 
FL7 (965 05E3 5,B8CD,8DC0) - 
F07 (69B97EB4) ->BAE2289A 
FI71 (57CF,4A6B) ->4 7F8 
seven 4F-> 57-> 7D- 
nine 0AF->0E5->0AA- 
FI72 (82 01, 7B4B) ->83AE 
seven 01-> 32-> 20- 
nine 104->013->012- 
FI73 (9AAB, 523E)->92 78 
seven 2B-> 78-> 42- 
nine 135->111->13A- 
Round 8 
F08 (CEB2F9B7) ->B7FB007B 
FI81 (52C3,7813) ->4A98 
seven 43-> 0B-> OF- 
nine 0A5->147->104- 
FI82 (C4A8,4A6B) ->04D4 
seven 28-> 65-> 6F- 
nine 189->022->00A- 
FI83 (6E3B,AA32) ->B780 
seven 3B-> 07-> OD- 
nine 0DC->031->00A- 
FL8 (B7FB007B, 63E7, 7B4B) - 
Output: DE551988 CEB2F9B7 



> 6C-> 44- 
>18B->1FD- 



> 2A-> 28- 
>051->197- 



> 08-> 26- 
>155->103- 



> 55 
>191 



> 15 
>1BD 



> 2D 
>10B 



> 29-> 7F- 
>102->07D- 


> 2B 
>054 


> 7E-> 3B- 
>18B->1FD- 


> 38 
>183 


> 13-> 72- 
>182->157- 
>81253B2F 


> 36 
>144 


>69B97EB4 




> 58-> 5B- 
>0C1->1A0- 


> 23 
>1F8 


> lD-> 6F- 
>159->1B3- 


> 41 
>1AE 


> 6B-> 31- 
>104->013- 


> 49 
>078 



> 33-> 3D- 
>117->0AB- 


> 25 
>098 


> 4A-> 56- 
>061->09E- 


> 02 
>0D4 


> 58-> 5B- 
>038->lD8- 
>480547BD 


> 5B 
>180 



3.5 



Test Set 3 



Key: 40 35 C6 68 OA F8 C6 Dl A8 FF 86 67 Bl 71 40 13 

input: 62 A5 40 98 IB A6 F9 B7 

output: 45 92 BO E7 86 90 F7 IB 

Key schedule : 





1 


2 


3 


4 


5 


6 


7 


8 


KLiI 


806A 


8CD1 


15F0 


8DA3 


51 FF 


OCCF 


62E3 


8026 


KLi2 


8353 


0B3E 


5623 


3CFF 


C725 


7203 


4116 


830F 


KOil 


CD18 


5F01 


DA38 


1FF5 


CCFO 


2E36 


0268 


06A8 


K0i2 


6786 


71 B1 


1340 


3540 


68C6 


F80A 


D1C6 


FFA8 


K0i3 


362E 


6802 


A806 


18CD 


015F 


38DA 


F51F 


FOCC 


Klil 


5623 


3CFF 


C725 


7203 


4116 


830F 


8353 


0B3E 


Kli2 


0B3E 


5623 


3CFF 


C725 


7203 


4116 


830F 


8353 


Kli3 


7203 


4116 


830F 


8353 


0B3E 


5623 


3CFF 


C725 



Input: 62A54098 1BA6F9B7 

Round 1 
FLl (62A54098, 806A, 8353) ->E51240D8 
FOl (E51240D8) ->B2CC3045 
Fill (2 80A, 5623) ->CED6 

seven 0A-> 3F-> 40-> 6B-> 31-> 67 
nine 05 0->lF5->lFF->lDC->0BD->0D6 
FI12 (275E, 0B3E) ->3CC2 

seven 5E-> lC-> 62-> 67-> 5C-> IE 
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nine 04E->12 0->17E->04 0->0A5->0C2 
FI13 (B820,7203) ->8289 

seven 20-> 35-> 0B-> 32-> 48-> 41 
nine 170->19E->lBE->lBD->0BB->0 8 9 

Round 2 
F02 (A96AC9F2) ->A4AC83B6 
FI21 (F66B,3CFF) ->0F18 

seven 6B-> 31-> 7F-> 61-> lF-> 07 
nine 1EC->12 5->14E->1B1->179->118 
FI22 (B84 3,5 62 3) ->624 6 

seven 43-> 0B-> 56-> 7D-> 77-> 31 
nine 17 0->19E->lDD->lFE->03B->04 6 
FI23 (AEE8,4116) ->271A 

seven 68-> 25-> 01-> 21-> 09-> 13 
nine 15D->14C->124->032->13B->llA 
FL2 (A4AC83B6, 8CD1, 0B3E) ->B3D38AB7 

Round 3 
FL3 (D176CA2F, 15F0, 5623) ->2CA9E8CF 
F03 (2CA9E8CF) ->C1983ADB 
FI31 (F6 91,C72 5) ->4 756 

seven ll-> 71-> 23-> 40-> 75-> 23 
nine lED->14 3->152->0 77->116->15 6 
FI32 (FB8F, 3CFF) ->6E01 

seven 0F-> 21-> lE-> 00-> 36-> 37 
nine 1F7->1B0->1BF->14 0->0 01->0 01 
FI33(07 9F,830F) ->FB4 3 

seven lF-> 51-> 43-> 02-> 3E-> 7D 
nine 00F->18D->192->0 9D->141->143 

Round 4 
F04 (68F2F329) ->3279F0E1 
FI41 (770 7, 72 03) ->54CC 

seven 07-> 60-> 59-> 60-> 66-> 2A 
nine 0EE->03E->03 9->03A->0AC->0CC 
FI42 (C669,C725) ->959C 

seven 69-> 4A-> 29-> 4A-> 56-> 4A 
nine 18C->0 8A->0E3->1C6->1D6->19C 
FI4 3 (BF2 8,83 53) ->C2 98 

seven 28-> 65-> 63-> 22-> 79-> 61 
nine 17E->12E->106->055->0BA->098 
FL4 (3279F0E1, 8DA3, 3CFF) ->CB86F0A3 
Round 5 
FL5 (1AF03A8C, 51FF,C725) ->A42B1B6C 
FOB (A42B1B6C) ->A62197C6 
FI51 (6 8DB,4116) ->0 6CF 

seven 5B-> 67-> 62-> 42-> 4C-> 03 
nine 0Dl->0DE->0 85->193->0 8D->0CF 
FI52 (73AA, 7203) ->BB82 

seven 2A-> 28-> 6D-> 54-> 5F-> 5D 
nine 0E7->1EF->1C5->1C6->1D6->182 
FI53 (ICFC, 0B3E) ->31E7 

seven 7C-> 58-> 2C-> 29-> 7F-> 18 
nine 03 9->108->174->04A->lCE->lE7 
Round 6 
F06 (CED364EF) ->D6DA665D 
FI61 (E0E5,83 0F) ->A72 7 

seven 65-> 04-> 00-> 41-> 74-> 53 
nine 1C1->161->104->0 0B->166->12 7 
FI62 (9CE5,4116) ->1512 

seven 65-> 04-> 53-> 73-> 18-> OA 
nine 13 9->0B2->0D7->1C1->161->112 
FI63 (FB12,562 3) ->B0 8 7 

seven 12-> 27-> 7F-> 54-> 5F-> 58 
nine lF6->0CA->0D8->0FB->0D3->0 8 7 
FL6 (D6DA665D, OCCF, 7203) ->294C6FC9 
Round 7 
FL7 (3 3BC554 5,62E3,4116) ->919210 05 
F07 (919210 05) ->4 84 3 93F4 
FI71 (93FA, 83 53) ->82E2 

seven 7A-> 0F-> lB-> 5A-> 23-> 41 
nine 12 7->0EE->0 94->lC7->0B8->0E2 
FI72 (C1C3, 830F) - >DAA4 

seven 43-> 0B-> 58-> 19-> 49-> 6D 
nine 183->090->0D3->lDC->0BD->0A4 
FI73 (67F8, 3CFF) ->DBB7 

seven 78-> 2A-> 48-> 56-> 5A-> 6D 
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nine 0CF->11A->162->19D->1E1->1B7 
Round 8 
F08 (8690F71B) ->B971E5E3 
FI81 (803 8, 0B3E) ->7 9B9 

seven 38-> 4D-> 56-> 53-> 05-> 3C 
nine 10 0->023->01B->125->lEA->lB9 
FI82 (0 8B3,83 53) ->3 7D3 

seven 33-> 3D-> 73-> 32-> 48-> IB 
nine 011->0FD->0CE->19D->1E1->1D3 
FI83 (7E6E,C725) ->5C92 

seven 6E-> 73-> 46-> 25-> 3C-> 2E 
nine 0FC->15B->135->010->0B7->092 
FL8 (B971E5E3, 8026, 830F) ->762EE5A2 
Output: 4592B0E7 8690F71B 



3.6 



Test Set 4 



This test ensures that all entries in the two S -boxes are correct. It does this by ensuring that every S-box entry is used at 
least once during the running of the test set. 

For a fixed key an initial input value, the algorithm is executed 50 times. The first encryption operates on the given 
input data. Each subsequent encryption takes the output of the previous encryption as its input data. After 50 
operations the output should be as shown below. 

Iterated test for full S-box coverage 

Key = 3A 3B 39 B5 C3 F2 37 6D 69 F7 D5 46 E5 F8 5D 43 
Input = CA 49 CI C7 57 71 AB OB 

After 5 repeated encryptions 
Output = 73 8B AD 4C 4A 69 08 02 



4.1 



Confidentiality algorithm f8 



Overview 



The test data sets presented here are for the/5 confidentiality algorithm. No detailed data is presented for the internal 
states of KASUMI as that is covered in section 3. 



4.2 



Format 



Each test set starts by showing the various inputs to the algorithm including the data stream to be encrypted/decrypted. 
(The length field is in decimal). This is followed by: 

the initial value of the variable A. 

the modified key used in the calculation KASUMI[ A ]ck©mk 

the result of the above operation. 

Thereafter four columns of data are shown. 

Column 1 shows the value of the block counter BLKCNT. 

KASUMI Input shows the input to the KASUMI block cipher, i.e. it is the bit- wise exclusive-or of the data in 
column 1 with the previous block of key stream and with the modified value of A. 

Keystream shows the 64-bit output from KASUMI. 

Enc/dec data shows the modified input data, i.e. it is the bit- wise exclusive-or of the corresponding keystream 
and the input data to the algorithm. As this is a stream cipher it is purely a matter of context 
whether the operation is regarded as "encryption" or "decryption". 
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4.3 



Test Set 1 



2BD64 5 9F82C5B3 952C4 9104 8 81FF4 8 

72A4F20F 

OC 

1 

798 bits 



Key 

Count 

Bearer 

Direction 

Length 

Plaintext : 

7EC61272743BF161 4726446A6C38CED1 66F6CA76EB543004 4286346CEF130F92 

922B03450D3A9975 E5BD2EA0EB55AD8E 1B199E3EC4316020 E9A1B285E7627953 

59B7BDFD39BEF4B2 484583D5AFE082AE E638BF5FD5A60619 3 901A0 8F4AB41AAB 

9B134880 



Initial A = 72A4F20F64000000 

Key used = 7E8310CAD790E655C0791C451DD4AA1D 

Modified A = 34222BC8F7C39416 

Key now = 2BD6459F82C5B300952C49104881FF48 



BLKCNT Kasumi input 



Keystream 



enc/dec data 



34222BC8F7C39416 

1 9B06E7CA6D00091F 

2 17FF3B89592F3A6F 

3 ED7EF11ABC04823A 

4 0BBD81D477124F09 

5 B35A01E4EA0AA415 

6 D0B9878C00D8129C 

7 911BA24116C94BA2 

8 D45DC154DBE30554 

9 3B615FAE070B3C02 

10 2FD678A6DA5A94D8 

11 09A6C1B5CB705324 

12 AB3B2EE0489F19B9 



AF24CC029AC39D08 
2 3DD1041AEECAE7B 
D95CDAD24BC7162F 
3F9FAA1C80D1DB1B 
87782A2C1DC93006 
E49BAC44F71B868C 
A5398989E10ADFB3 
E07FEA9C2C20914A 
0F437466F0C8A81D 
1BF4536E2D9900C4 
3D84EA7D3CB3C739 
9F190528BF5C8DA3 
082A2D8F25915EE3 



D1E2DE70EEF86C69 
64FB542BC2D460AA 
BFAA10A4A093262B 
7D199E706FC2D489 
1553296910F3A973 
012682E41C4E2B02 
BE2017B7253BBF93 
09DE5819CB42E819 
56F4C99BC9765CAF 
53B1D0BB8279826A 
DBBC5522E915C120 
A618A5A7F5E89708 
9339650F 



4.4 



Test Set 2 



Key 

Count 

Bearer 

Direction 

Length 

Plaintext : 

10111231E060253A 43FD3F57E37607AB 2827B599B6B1BBDA 37A8ABCC5A8C550D 

1BFB2F494624FB50 367FA36CE3BC68F1 1CF93B1510376B02 130F812A9FA169D8 



EFA8B222 9E72 0C2A7C3 6EA55E96 056 95 

E28BCF7B 

18 



510 bits 



Initial A = E28BCF7BC0000000 

Key used = BAFDE777CB27597F2963BF00BC3503C0 

Modified A = 1C05EA5F90964036 

Key now = EFA8B2229E720C2A7C36EA55E9605695 



BLKCNT Kasumi input 



Keystream 



enc/dec data 



1C05EA5F90964036 

1 31FE3412657479A7 

2 D6161FD6E8BB94FE 

3 7FF29787BB56F86A 

4 F61319DA2501B965 

5 EF4F8F4DDCD5FA31 

6 34CEA938CAC6DB28 

7 F730688067E079E4 



2DFBDE4DF5E23990 
CA13F589782DD4CA 
63F77DD82BC0B85F 
EA16F385B597F957 
F34A65124C43BA02 
28CB43675A509B18 
EB3582DFF77639D5 
E7ED211E294B6934 



3DEACC7C15821CAA 
89EECADE9B5BD361 
4BD0C8419D710385 
DDBE5849EF1BAC5A 
E8B14A5B0A674152 
1EB4E00BB9ECF3E9 
F7CCB9CAE74152D7 
F4E2A034B6EA00EC 
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4.5 



Test Set 3 



Key = 5ACB1D644C0D51204EA5F1451010D852 

Count = FA556B2 6 

Bearer = 03 

Direction = 1 

Length = 120 bits 

Plaintext : 

AD9C441F890B38C4 57A49D421407E8 

Initial A = FA556B261C000000 

Key used = 0F9E4831195804751BF0A41045458D07 

Modified A = 3E5A6D0A3D1C82A5 

Key now = 5ACB1D644C0D51204EA5F1451010D852 



BLKCNT Kasumi input 



Keystream 



enc/dec data 



3E5A6D0A3D1C82A5 365568B78ACD43EC 9BC92CA803C67B2E 

1 080F05BDB7D1C148 F6BED6AC4E0BCD5F A11A4BEE5A0C25 



4.6 



Test Set 4 



D3C5D5 92 32 7FB11C4 03 5C6 6 8 0AF8C6D1 

398A59B4 

05 

1 

253 bits 



Key 

Count 

Bearer 

Direction 

Length 

Plaintext : 

981BA6824C1BFB1A B485472029B71D80 8CE33E2CC3C0B5FC 1F3DE8A6DC66B1F0 



Initial A = 398A59B42C000000 

Key used = 869080C7672AE4491560933D5FAD9384 

Modified A = F04B50A2A852469C 

Key now = D3C5D592327FB11C4035C6680AF8C6D1 



BLKCNT Kasumi input 



Keystream 



enc/dec data 



F04B50A2A852469C C3A2E599FDF270CB 5BB9431BB1E98BD1 

1 33E9B53B55A03656 AF169C5C14F20EE5 1B93DB7C3D451365 

2 5F5DCCFEBCA0487B D558B88E566A95B2 59BB86A295AA204E 

3 2513E82CFE38D32D D4D61E517976A4E2 CBEBF6F7A5101512 
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4.7 Test Set 5 

Key = 6090EAE04C83706EECBF652BE8E36566 

Count = 72A4F2 0F 

Bearer = 09 

Direction = 

Length = 837 bits 

Plaintext : 

40981BA6824C1BFB 4286B299783DAF44 2C099F7AB0F58D5C 8E46B104F08F01B4 

1AB485472029B71D 36BD1A3D90DC3A41 B46D51672AC4C966 3A2BE063DA4BC8D2 

808CE33E2CCCBFC6 34E1B259060876A0 FBB5A437EBCC8D31 C19E4454318745E3 

987645987A986F2C BO 

Initial A = 72A4F20F48000000 

Key used = 35C5BFB519D6253BB9EA307EBDB63033 

Modified A = 1EDF994571692FEA 

Key now = 6090EAE04C83706EECBF652BE8E36566 

BLKCNT Kasumi input Keystream enc/dec data 

1EDF994571692FEA 9D2B7F7BA8E2D9B6 DDB3 64DD2AAEC24D 

1 83F4E63ED98BF65D BDAFABCECFB6 024 2 FF291957B78BAD06 

2 A3 7 032 8BBEDF2DAA 16CCE6B720B437E2 3AC579CD9041BABE 

3 08137FF251DD180B 07BBA858F5F7CA2B 89FD195C0578CB9F 

4 1964311D849EE5C5 C4F692114151651F DE4217566178D202 

5 DA290B5430384AF0 769D773A5F7A23AD 40206D07CFA619EC 

6 6842EE7F2E130C41 B1F232366E9D3576 059F63514459FC10 

7 AF2DAB731FF41A9B EE0629F0941D2312 D42DC9934E56EBC0 

8 F0D9B0B5E5740CF0 4B4AEE73013DCBB1 CBC60D4D2DF17477 

9 559577367054E452 785C7F04A2AB2691 4CBDCD5DA4A35031 

10 6683E641D3C20971 81CAB6D67F58FCC9 7A7F12E1949471F8 

11 9F152F930E31D328 630BB626D7088592 A295F272E68FC071 

12 7DD42F63A661AA74 C1C6381657BE8B75 59B07D8E2D26E459 

13 DF19A15326D7A492 2E1EA0BF8D97DA88 9E 



Integrity algorithm f9 



5.1 Overview 

The test data sets presented here are for the/9 integrity algorithm. No detailed data is presented for the internal states of 
KASUMI as that is covered in section 3. 

5.2 Format 

The test data set shows the input values to the algorithm. 

Following this it shows four columns of data; input, KASUMI input, KASUMI output and the cumulative exclusive- 
OR where: 

Input is the plain text input block that is being hashed. It commences with the value COUNT II FRESH 

and is followed by the MESSAGE. The final input block includes the DIRECTION bit and the 
padding. 

KASUMI Input is the input value to the block cipher. In the first line this is COUNT II FRESH, subsequently it is 
the XOR of the plain text block and the previous output from KASUMI. 

KASUMI Output is the output of the block cipher 

Accumulated XOR is the XOR of all the output of all the KASUMI operations performed up to that point. 

Finally the modified key is shown along with the input and output data from the last application of KASUMI. 
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5.3 



Test Set 1 



Key 

Count 

Fresh 

Direction 

Length 

Message : 

6B227737296F393C 8079353EDC87E2E8 05D2EC49A4F2D8E0 



2BD64 5 9F82C5B3 952C4 9104 8 81FF4 8 

38A6F056 

05D2EC49 



189 bits 



Input 



Kasumi input 



Kasumi Output 



Accumulated XOR 



38A6F05605D2EC49 38A6F05605D2EC49 89E0A6D036C17090 89E0A6D036C17090 

6B227737296F393C E2C2D1E71FAE49AC 45C16C0142460205 CC21CAD174877295 

8079353EDC87E2E8 C5B8593F9EC1E0ED E24CFA7D8471E4DD 2E6D30ACF0F69648 

05D2EC49A4F2D8E2 E79E163420833C3F DFD3DCB9499275BA F1BEEC15B964E3F2 



New Key: 817CEF35286F19AA3F86E3BAE22B55E2 

final step: F1BEEC15B964E3F2 F63BD72C702EBC7A 

MAC-I: F63BD72C 



5.4 



Test Set 2 



Key 

Count 

Fresh 

Direction 

Length 

Message : : 

B5924384328A4AE0 0B737109F8B6C8DD 2B4DB63DD533981C EB19AAD52A5B2BC0 



D42F6 8242 82 01CAFCD9F9794 5E6DE7B7 

3EDC87E2 

A4F2D8E2 

1 

254 bits 



Input 



Kasumi input 



Kasumi Output 



Accumulated XOR 



3EDC87E2A4F2D8E2 
B5924384328A4AE0 
0B737109F8B6C8DD 
2B4DB63DD533981C 
EB19AAD52A5B2BC3 



3EDC8 7E2A4F2D8E2 3 541B4 73 3 9DD416 8 

8 0D3F7F7 0B5 7 0B8 8 52EC81194ECEDDA0 

5 99FF010B6 7 815 7D 7 92BFE1F0 7A1A8B0 

52 6 64 822D2 92 3 0AC C92F7E2C3 8D22B6D 

2236D4F912 890 0AE 4C2BEF9C822 3 34 03 



3541B47339DD4168 
67AD356A77139CC8 
1E86CB7570B23478 
D7A9B55948601F15 
9B825AC5CA432B16 



New Key: 7E85C28E828AB60567353D3EF4C74D1D 

final step: 9B825AC5CA432B16 A9DAF1FF12F71DE7 

MAC-I: A9DAF1FF 



5.5 Test Set 3 



Key 

Count 

Fresh 

Direction 

Length 

Message : : 

5932BC0ACE2B0ABA 33D8AC188AC54F34 6FAD10BF9DEE2920 B43BD0C53A915CB7 

DF6CAA72 053ABFF2 



FDB9CFDF2 8 93 6CC4 83A3186 9D81B8FAB 

36AF6144 

9838F03A 

1 

319 bits 



Input 



Kasumi input 



Kasumi Output 



Accumulated XOR 



36AF61449838F03A 
5932BC0ACE2B0ABA 
33D8AC188AC54F34 
6FAD10BF9DEE2920 
B43BD0C53A915CB7 
DF6CAA72 053ABFF3 
8000000000000000 



36AF61449838F03A 
849556A85C9B1A56 
0EBD5DF3EB910916 
72CFC6A1C3375D11 
A0F2B87FFE69FE12 
B26D9820195B1AA1 
3F04729B5C03EA98 



DDA7EAA292B010EC 
3D65F1EB61544622 
1D62D61E5ED97431 
14C96 8BAC4F8A2A5 
6D0132521C61A552 
BF04729B5C03EA98 
8B0C8BE27C74D17F 



DDA7EAA292B010EC 
E0C21B49F3E456CE 
FDA0CD5 7AD3D22FF 
E969A5ED69C5805A 
846897BF75A42508 
3B6CE52429A7CF90 
B0606EC655D31EEF 



New Key: 571365758239C66E2909B2C372B12501 

final step: B0606EC655D31EEF 1537D316633A8831 

MAC-I: 1537D316 
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5.6 



Test Set 4 



Key 

Count 

Fresh 

Direction 

Length 

Message : : 

D0A7D463DF9FB2B2 78833FA02E235AA1 72BD970C1473E129 07FB648B6599AAA0 

B24A03 8 6 65422B2 A4 992 76A5 042 70 09 



C73 6C6AAB22BFFF91E2 6 98D2E22AD57E 

14793E41 

0397E8FD 

1 

384 bits 



Input 



Kasumi input 



Kasumi Output Accumulated XOR 



14793E410397E8FD 
D0A7D463DF9FB2B2 
78833FA02E235AA1 
72BD970C1473E129 
07FB648B6599AAA0 
B24A038665422B20 
A499276A50427009 
COOOOOOOOOOOOOOO 



14793E410397E8FD 
2BCD8BD64136A9E5 
A57530894673F4F5 
880AF1466B57A6CE 
E1BF52CC84B13AA7 
6863938E57A8675C 
D05BD2D2476C4614 
B9AA12C36369E686 



FB6A5FB59EA91B57 
DDF60F296850AE54 
FAB7664A7F2447E7 
E6443647E1289007 
DA29900832EA4C7C 
74C2F5B8172E361D 
79AA12C36369E686 
A464F43DEE74E0C7 



FB6A5FB59EA91B57 
269C509CF6F9B503 
DC2B36D689DDF2E4 
3A6F009168F562E3 
E04690995A1F2E9F 
948465214D311882 
ED2E77E22E58FE04 
494A83DFC02C1EC3 



New Key: 6D9C6C0018815553B48C327848807FD4 

final step: 494A83DFC02C1EC3 DD7DFADDD68D1EC1 

MAC- I: DD7DFADD 



5.7 Test Set 5 



F4EBEC6 9E73EAF2EB2CF6AF4B312 0FFD 

296F393C 

6B227737 

1 

1000 bits 



Key 

Count 

Fresh 

Direction 

Length 

Message : : 

10BFFF839E0C7165 8DBB2D1707E14572 4F41C16F48BF403C 3B18E38FD5D1663B 

6F6D900193E3CEA8 BB4F1B4F5BE82203 2232A78D7D75238D 5E6DAECD3B4322CF 

59BC7EA84AB18811 B5BFB7BC553F4FE4 4478CE287A148799 90D18D12CA79D2C8 

55149021CD5CE8CA 0371CA04FCCE143E 3D7CFEE94585B588 5CAC46068B 



Input 



Kasumi input 



Kasumi Output 



Accumulated XOR 



296F393C6B227737 
10BFFF839E0C7165 
8DBB2D1707E14572 
4F41C16F48BF403C 
3B18E38FD5D1663B 
6F6D900193E3CEA8 
BB4F1B4F5BE82203 
2232A78D7D75238D 
5E6DAECD3B4322CF 
59BC7EA84AB18811 
B5BFB7BC553F4FE4 
4478CE287A148799 
90D18D12CA79D2C8 
55149021CD5CE8CA 
0371CA04FCCE143E 
3D7CFEE94585B588 
5CAC46068BC00000 



296F393C6B227737 
574955188BFBD772 
E1C75CEAEE4B6EFF 
264347FF2581FA82 
AF338647CC5BDF0D 
3F3F381B89E65518 
5F405EED70A9925C 
B3F2A8C4076FA214 
809DFD3675F11D25 
E7753407B486ABDD 
2E6B7CDC3CBA5D9A 
91AD66C6B74508D7 
8768AD2D09254A4A 
757EA6B2C433D82D 
CC521818D9AE72D7 
FFA8F413F9175776 
353127BB5BF6A7E5 



47F6AA9B15F7A617 
6C7C71FDE9AA2B8D 
690286906D3EBABE 
942B65C8198AB936 
5052A81A1A059BB0 
E40F45A22B41B05F 
91C00F497A1A8199 
DEF053FB4EB2 3FEA 
BEC94AAFFE3 723CC 
9BD4CB606985127E 
D5D5A8EECD518F4E 
17B9203FC35C9882 
206A3693096F30E7 
CF23D21C256066E9 
C2D4 0AFABC92E2FE 
699D61BDD036A7E5 
E3D8AE061C3A3C87 



47F6AA9B15F7A617 
2B8ADB66FC5D8D9A 
42885DF691633724 
D6A3383E88E98E12 
86F1902492EC15A2 
62FED586B9ADA5FD 
F33EDACFC3B72464 
2DCE89348D051B8E 
9307C39B73323842 
08D308FB1AB72A3C 
DD06A015D7E6A572 
CABF8 02A14BA3DF0 
EAD5B6B91DD50D17 
25F664A538B56BFE 
E7226E5F84278900 
8EBF0FE254112EE5 
6D67A1E4482B1262 



New Key: 5E4146C34D9405841865C05E19B8A557 

final step: 6D67A1E4482B1262 C383839D93FFC6D1 

MAC-I: C383839D 
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